Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-98

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

1,269
Assigned CVEs
44th
Commonality Rank
8.1
Avg CVSS
0.1%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-98 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 19, 2018
8 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

1,269 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-68645HIGH
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parame
Dec 22, 20258.890YESYES
CVE-2023-49084HIGH
Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient proc
Dec 21, 20238.872NOYES
CVE-2023-6989CRITICAL
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via
Feb 5, 20249.871NOYES
CVE-2024-5762HIGH
Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation
Aug 21, 20248.162NONO
CVE-2026-0926CRITICAL
The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'parameters[template_name]' parameter. This make
Feb 19, 20269.860NOYES
CVE-2023-2249HIGH
The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is du
Jun 9, 20238.857NONO
CVE-2025-4380CRITICAL
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.89 via the 'bsa_
Jul 2, 20259.855NOYES
CVE-2022-4606CRITICAL
PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.
Dec 18, 20229.852NONO
CVE-2024-12209CRITICAL
The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' param
Dec 8, 20249.851NOYES
CVE-2012-10025CRITICAL
The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP configuratio
Aug 5, 202510.048NOYES
View all 1,269 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
19%
5.0-5.9
16%
6.0-6.9
25%
26%
7.0-7.9
61%
11%
8.0-8.9
10%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
1 CVE
0.1% of CVEs· 79th percentile
Metasploit
3 CVEs
0.2% of CVEs· 80th percentile
Nuclei
13 CVEs
1.0% of CVEs· 85th percentile
ExploitDB
4 CVEs
0.3% of CVEs· 75th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products